IT, Cloud & DevOps Blog

Ubuntu 16.04 — mcabber — vulnerability — patch and remediation guide — diagnosis and fix on Ubuntu 16.04

Ubuntu 16.04 — mcabber — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 8 July 2016 Affected versions: Ubuntu 16.04 (xenial) 📖 ~4 min read  •  Source: Ubuntu Security Notice USN-4506-1 Related CVEs: CVE-2016-9928 Upstream summary: It was discovered that MCabber does not properly manage roster pushes. An attacker could possibly use this issue to remotely perform machine-in-the-middle attacks. (CVE-2016-9928). […]

Read more
Ubuntu 14.04 — libvdpau — multiple vulnerabilities (3 CVEs) — patch and remediation guide — diagnosis and fix on Ubuntu 14.04

Ubuntu 14.04 — libvdpau — multiple vulnerabilities (3 CVEs) — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 8 July 2016 Affected versions: Ubuntu 14.04 (trusty) 📖 ~4 min read  •  Source: Ubuntu Security Notice USN-2729-1 Related CVEs: CVE-2015-5198 CVE-2015-5199 CVE-2015-5200 Upstream summary: Florian Weimer discovered that libvdpau incorrectly handled certain environment variables. A local attacker could possibly use this issue to gain privileges. Table […]

Read more
IBM AIX 7.2 — CVE-1999-0078 — vulnerability — patch and remediation guide — diagnosis and fix on IBM AIX 7.2

IBM AIX 7.2 — CVE-1999-0078 — vulnerability — patch and remediation guide

🟢 Low   ⏱ 10–30 min  Last verified: 2 July 2016 Affected versions: IBM AIX 7.2 📖 ~4 min read  •  Source: NVD CVE-1999-0078, IBM PSIRT advisory page CVE: CVE-1999-0078 NVD summary: pcnfsd (aka rpc.pcnfsd) allows local users to change file permissions, or execute arbitrary commands through arguments in the RPC call. References: exchange.xforce.ibmcloud.com/vulnerabilities/CVE   […]

Read more
IBM AIX 7.2 — CVE-2004-0545 — vulnerability — patch and remediation guide — diagnosis and fix on IBM AIX 7.2

IBM AIX 7.2 — CVE-2004-0545 — vulnerability — patch and remediation guide

🟠 High   ⏱ 30–90 min  Last verified: 2 July 2016 Affected versions: IBM AIX 7.2 📖 ~4 min read  •  Source: NVD CVE-2004-0545, IBM Support Bulletin CVE: CVE-2004-0545 NVD summary: LVM for AIX 5.1 and 5.2 allows local users to overwrite arbitrary files via a symlink attack. References: www-1.ibm.com/services/continuity/recover1.nsf/m   www.ciac.org/ciac/bulletins/o-131.shtml   www.securityfocus.com/bid/10230 Table […]

Read more
IBM AIX 7.1 — CVE-2015-9281 — vulnerability — patch and remediation guide — diagnosis and fix on IBM AIX 7.1

IBM AIX 7.1 — CVE-2015-9281 — vulnerability — patch and remediation guide

🟡 Medium   ⏱ 15–45 min  Last verified: 30 June 2016 Affected versions: IBM AIX 7.1 📖 ~4 min read  •  Source: NVD CVE-2015-9281, IBM PSIRT advisory page CVE: CVE-2015-9281 NVD summary: Logon Manager in SAS Web Infrastructure Platform before 9.4M3 allows reflected XSS on the Timeout page. References: support.sas.com/kb/55/537.html   support.sas.com/kb/55/537.html Table of contents […]

Read more
CHAT